CVE-2023-39319

Publication date

2023-09-08 16:13:28

Family

Go

State

PUBLISHED

Description

The html/template package does not apply the proper rules for handling occurrences of " contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.